[El] Mapserver binary path and some possible security issues

Volker Fröhlich volker27 at gmx.at
Fri Apr 15 15:45:40 EDT 2011


Dear list readers!

The mapserver binary currently goes to %{_sbindir}. This does not comply with 
the File Hierarchy Standard and was considered a serious security problem as 
well, being discussed on #fedora-devel.

Much rather, the binary should go to %{_libexecdir}. Please see:

http://www.pathname.com/fhs/pub/fhs-2.3.html#SBINSYSTEMBINARIES
http://fedoraproject.org/wiki/PackagingGuidelines#Libexecdir

I'm aware, this path is also wrong in Fedora, but I don't feel like taking all 
the load of the world on my back, since this is none of my packages in Fedora.

Besides that, you might be interested in this ticket: 
https://bugzilla.redhat.com/show_bug.cgi?id=617301

I haven't cross-checked whether you patch this out, but the Fedora package is 
not really active, hence I tell you.

Volker Fröhlich


More information about the el mailing list